Back to Field Notes
Identity & Access/Field Note

Passwordless — A Realistic Multi-Year Roadmap

Passwordless takes 24-36 months in most enterprises. The roadmap is well-known; the discipline is what is hard.

Author

Yusuf Ahmed

Principal Engineer, Platform Security

Published

March 13, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Going passwordless across an enterprise typically takes 24-36 months. Technology is ready; legacy applications, recovery flows, user education, and residual edge cases extend the timeline.
  • 02Year 1 (foundation): modern IdP with WebAuthn/passkey support enabled, MFA universal across the workforce, passkey enrollment opt-in for early adopters, inventory of every authentication method in the estate.
  • 03Year 2 (transition): passkey enrollment promoted as the default, password-less sign-in option, legacy apps migrated to SAML/OIDC, recovery flows tightened (recovery is the new attack surface).
  • 04Year 3 (completion): passwordless is default for new accounts, remaining password-required apps catalogued and on a retirement plan, recovery hardened. Roadmaps die on legacy app inventory and recovery flow design — protect the program from skipping either step under deadline pressure.

Going passwordless across an enterprise typically takes 24 to 36 months. The technology is ready; the legacy applications, the recovery flows, the user education, and the residual edge cases are what extend the timeline.

Year 1 — Foundation

  • 01Modern IdP with WebAuthn/passkey support enabled
  • 02MFA universal across the workforce
  • 03Passkey enrollment opt-in for early adopters
  • 04Inventory of every authentication method in the estate

Year 2 — Transition

Passkey enrollment promoted as the default. Password-less sign-in option for sign-in flows. Legacy applications migrated to SAML/OIDC where they are not already. Password reset flows tightened (the recovery story is the new attack surface).

Year 3 — Completion

Password-less is the default for new accounts. Remaining password-required applications are explicitly catalogued and on a retirement plan. Recovery flows are reviewed and hardened. The remaining password population is the small set of legacy systems with no path forward — typically isolated and monitored as a result.

Where roadmaps die

The legacy app inventory is always larger than expected. The recovery flow always takes longer to design than expected. Plan for both, and protect the program from the temptation to skip either step under deadline pressure.

#Passwordless#Passkeys#Authentication

/WRITTEN_BY

Yusuf Ahmed

Principal Engineer, Platform Security · Alexa Cybersecurity